
CVE-2026-2427 The itsukaita plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'day_from' and 'day_to' parameters in all versions up to, and including, 0.1.… https://www.cve.org/CVERecord?id=CVE-2026-2427
Post summary
The post announces a reflected XSS flaw in the itsukaita WordPress plugin, specifying vulnerable parameters, but offers no evidence of exploitation, patches, or PoC.
